Corelan Research

Two decades of exploit development research, techniques, and knowledge β€” shared openly and for free with the community.

Quick links:

πŸ“‘ Exploit Development 
tutorials

πŸŽ₯​ Exploit Development 
videos

πŸ“š Tutorials on Debugging

🧑 Support us

⭐️ Exploit Development training

All articles:

 BlackHatEU2013 - Day1 - Practical Attacks against MDM solutions

Good morning everyone, Welcome to BlackHat Europe 2013 ! Β As announced in my post a couple of days ago, I'll try to post short write-ups about some…

​ Read More

 Black Hat Europe 2013 - Preview

  Hola dear friends, There's only a few days left until Black Hat Europe 2013 opens its doors in the beautiful city of Amsterdam, the …

​ Read More

 Root Cause Analysis – Memory Corruption Vulnerabilities

Introduction For the past year or so I've spent a significant amount of time fuzzing various applications with the hopes of identifying exploitable…

​ Read More

 DEPS - Precise Heap Spray on Firefox and IE10

Introduction Last week, while doing my bi-weekly courseware review and update, I discovered that my heap spray script for Firefox 9 no longer works…

​ Read More

 Heap Layout Visualization with mona.py and WinDBG

Introduction Time flies. Almost 3 weeks have passed since we announced the ability to run mona.py under WinDBG.  A lot of work has been done …

​ Read More

Corelan Research is a long-running cybersecurity research project focused on exploit development, vulnerability research and Windows internals.   Since 2009, we have published deep technical tutorials covering topics such as stack-based exploitation, heap exploitation, shellcoding, reverse engineering and debugging. 
These tutorials have helped thousands of security researchers, penetration testers, exploit developers and exploit dev trainers learn how modern memory corruption vulnerabilities work.